You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform创建基于kubeconfig的AKS服务连接遇插件崩溃求助

问题

尝试通过Terraform使用kubeconfig配置创建指向AKS的Azure DevOps服务连接,目标是自动化完成该服务连接的创建。使用以下配置后执行报错:

配置代码

data "azurerm_kubernetes_cluster" "aks-read" {
  name                = var.name
  resource_group_name = var.resource_group
}

resource "azuredevops_serviceendpoint_kubernetes" "serviceendpoint_kubernetes" {
  project_id            = data.azuredevops_project.p.id
  service_endpoint_name = var.service_endpoint_name
  apiserver_url         = var.apiserver_url
  authorization_type    = "AzureSubscription"

  kubeconfig {
    kube_config = data.azurerm_kubernetes_cluster.aks-read.kube_config_raw
  }
}

错误信息

Stack trace from the terraform-provider-azuredevops_v0.3.0 plugin:

panic: runtime error: index out of range [0] with length 0

goroutine 31 [running]:
github.com/microsoft/terraform-provider-azuredevops/azuredevops/internal/service/serviceendpoint.expandServiceEndpointKubernetes(0x0?)
        github.com/microsoft/terraform-provider-azuredevops/azuredevops/internal/service/serviceendpoint/resource_serviceendpoint_kubernetes.go:186 +0x128f
github.com/microsoft/terraform-provider-azuredevops/azuredevops/internal/service/serviceendpoint.genServiceEndpointCreateFunc.func1(0x0?, {0x189cc00?, 0xc0004b86c0})
        github.com/microsoft/terraform-provider-azuredevops/azuredevops/internal/service/serviceendpoint/commons.go:167 +0x73
github.com/hashicorp/terraform-plugin-sdk/v2/helper/schema.(*Resource).create(0x1b8bda0?, {0x1b8bda0?, 0xc00026fef0?}, 0xd?, {0x189cc00?, 0xc0004b86c0?})
        github.com/hashicorp/terraform-plugin-sdk/v2@v2.23.0/helper/schema/resource.go:695 +0x178
github.com/hashicorp/terraform-plugin-sdk/v2/helper/schema.(*Resource).Apply(0xc0003f1ce0, {0x1b8bda0, 0xc00026fef0}, 0xc0004b1790, 0xc000489a80, {0x189cc00, 0xc0004b86c0})
        github.com/hashicorp/terraform-plugin-sdk/v2@v2.23.0/helper/schema/resource.go:837 +0xa7a
github.com/hashicorp/terraform-plugin-sdk/v2/helper/schema.(*GRPCProviderServer).ApplyResourceChange(0xc0000d3620, {0x1b8bda0?, 0xc00026fdd0?}, 0xc00026a960)
        github.com/hashicorp/terraform-plugin-sdk/v2@v2.23.0/helper/schema/grpc_provider.go:1021 +0xe3c
github.com/hashicorp/terraform-plugin-go/tfprotov5/tf5server.(*server).ApplyResourceChange(0xc000282960, {0x1b8bda0?, 0xc00026ed50?}, 0xc0003b8310)
        github.com/hashicorp/terraform-plugin-go@v0.14.0/tfprotov5/tf5server/server.go:818 +0x574
github.com/hashicorp/terraform-plugin-go/tfprotov5/internal/tfplugin5._Provider_ApplyResourceChange_Handler({0x19f8c40?, 0xc000282960}, {0x1b8bda0, 0xc00026ed50}, 0xc0003b82a0, 0x0)
        github.com/hashicorp/terraform-plugin-go@v0.14.0/tfprotov5/internal/tfplugin5/tfplugin5_grpc.pb.go:385 +0x170
google.golang.org/grpc.(*Server).processUnaryRPC(0xc0003dc000, {0x1b8ea40, 0xc000190b60}, 0xc0002f4900, 0xc000424750, 0x20b0620, 0x0)
        google.golang.org/grpc@v1.48.0/server.go:1295 +0xb0b
google.golang.org/grpc.(*Server).handleStream(0xc0003dc000, {0x1b8ea40, 0xc000190b60}, 0xc0002f4900, 0x0)
        google.golang.org/grpc@v1.48.0/server.go:1636 +0xa1b
google.golang.org/grpc.(*Server).serveStreams.func1.2()
        google.golang.org/grpc@v1.48.0/server.go:932 +0x98
created by google.golang.org/grpc.(*Server).serveStreams.func1
        google.golang.org/grpc@v1.48.0/server.go:930 +0x28a

Error: The terraform-provider-azuredevops_v0.3.0 plugin crashed!

This is always indicative of a bug within the plugin. It would be immensely
helpful if you could report the crash with the plugin's maintainers so that it
can be fixed. The output above should help diagnose the issue.

解决方案

问题根源

  1. 授权类型冲突:配置中authorization_type设为AzureSubscription,但同时提供了kubeconfig块,两种授权方式不能混用,插件处理冲突配置时触发索引越界panic。
  2. 插件版本过旧:使用的azuredevops provider v0.3.0存在已知bug,对kubeconfig的处理逻辑不完善。

修复步骤及代码

方案1:使用Kubeconfig授权方式

将authorization_type改为Kubeconfig,并升级provider版本:

  1. 更新provider版本配置:
terraform {
  required_providers {
    azuredevops = {
      source  = "microsoft/azuredevops"
      version = ">= 0.6.0"
    }
    azurerm = {
      source  = "hashicorp/azurerm"
      version = ">= 3.0.0"
    }
  }
}
  1. 修正服务连接资源配置:
data "azurerm_kubernetes_cluster" "aks-read" {
  name                = var.name
  resource_group_name = var.resource_group
}

resource "azuredevops_serviceendpoint_kubernetes" "serviceendpoint_kubernetes" {
  project_id            = data.azuredevops_project.p.id
  service_endpoint_name = var.service_endpoint_name
  # 直接从AKS数据资源获取apiserver地址,避免手动输入错误
  apiserver_url         = data.azurerm_kubernetes_cluster.aks-read.kube_config.0.host
  authorization_type    = "Kubeconfig"

  kubeconfig {
    kube_config = data.azurerm_kubernetes_cluster.aks-read.kube_config_raw
  }
}

方案2:使用AzureSubscription授权方式(无需kubeconfig)

如果希望通过Azure订阅授权,移除kubeconfig块,添加azure_subscription配置:

data "azurerm_kubernetes_cluster" "aks-read" {
  name                = var.name
  resource_group_name = var.resource_group
}

resource "azuredevops_serviceendpoint_kubernetes" "serviceendpoint_kubernetes" {
  project_id            = data.azuredevops_project.p.id
  service_endpoint_name = var.service_endpoint_name
  apiserver_url         = data.azurerm_kubernetes_cluster.aks-read.kube_config.0.host
  authorization_type    = "AzureSubscription"

  azure_subscription {
    subscription_id   = var.azure_subscription_id
    subscription_name = var.azure_subscription_name
    tenant_id         = var.azure_tenant_id
  }
}

最终操作

执行terraform init -upgrade升级provider版本,之后再执行terraform apply即可完成服务连接创建。

内容的提问来源于stack exchange,提问作者Michele

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 06:45:22